CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
Ars Technica
We now have a better understanding how OpenAI hacked into Hugging Face
Last week’s unprecedented security event in which two OpenAI security hacking models trespassed into the network of fellow AI company Hugging Face was enabled by exploiting one or more zero-day vulner ...
-
TheCyberThrone
CVE-2026-63077: JetBrains TeamCity RCE
Executive SummaryModern software development depends on CI/CD platforms to automate code building, testing, and deployment. These platforms hold privileged credentials, source code, signing certificat ...
-
The Hacker News
24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before Login
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) pro ...
-
The Hacker News
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software rep ...
-
security.nl
'24.000 server-BMC's lekken wachtwoordhashes via 13 jaar oude kwetsbaarheid'
Onderzoekers hebben op internet ruim 24.000 Baseboard Management Controllers (BMC's) ontdekt die via een dertien jaar oude kwetsbaarheid wachtwoordhashes lekken, die vervolgens te kraken zijn. Een BM ...
-
The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2 ...
-
security.nl
Servers aangevallen via kritiek RCE-lek in Java-library FastJson
Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in de Java-library FastJson voor het aanvallen van servers, zo waarschuwen cybersecuritybedrijven. Een beveiligingsupdate voor de kwets ...
-
The Cyber Express
Tanaka Dominates Data Leak Landscape With 25 Leak Posts
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the dat ...
-
cert.pl
Vulnerability in Quick.Cart software
Vulnerability in Quick.Cart software CVE ID CVE-2026-41874 Publication date 28 July 2026 Vendor OpenSolution Product Quick.Cart Vulnerable versions All through 6.7 Vulnerability type (CWE) Plaintext S ...
-
cert.pl
Vulnerabilities in Quick.CMS software
Vulnerabilities in Quick.CMS software CVE ID CVE-2026-63301 Publication date 28 July 2026 Vendor OpenSolution Product Quick.CMS Vulnerable versions All through 6.8.0 Vulnerability type (CWE) Client-Si ...